CVE Prioritization
Triage CVEs by EPSS, CISA KEV, PoC availability, attack complexity, and in-feed incidents.
50
Total CVEs
6
Critical
0
KEV / Exploited
0
PoC Exists
0
Zero Day
0
Patch Available
| CVE ID | Published | Severity | EPSS Score | Complexity | Status | PoC | Patch | Due Date | Feed Hits | Description | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 30 Jul 2026 | HIGH 8.8 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to e | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to r | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive infor | Details | |
| 30 Jul 2026 | HIGH 7.3 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up. | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen | Details | |
| 30 Jul 2026 | CRITICAL 9.3 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site sc | Details | |
| 30 Jul 2026 | MEDIUM 5.4 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri | Details | |
| 30 Jul 2026 | MEDIUM 5.4 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera | Details | |
| 30 Jul 2026 | MEDIUM 5.4 |
0.0%
|
LOW |
—
|
— | — | — | 0 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 | Details | |
| 30 Jul 2026 | HIGH 8.8 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and sessio | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran | Details | |
| 30 Jul 2026 | HIGH 8.3 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows C | Details | |
| 30 Jul 2026 | MEDIUM 5.3 |
0.0%
|
LOW |
—
|
— | — | — | 0 | A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
HIGH |
—
|
— | — | — | 0 | e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a | Details | |
| 30 Jul 2026 | HIGH 8.1 |
0.0%
|
HIGH |
—
|
— | — | — | 0 | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly | Details | |
| 30 Jul 2026 | LOW 2.7 |
0.0%
|
LOW |
—
|
— | — | — | 0 | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform | Details | |
| 30 Jul 2026 | HIGH 8.2 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel a | Details | |
| 30 Jul 2026 | CRITICAL 9.8 |
0.0%
|
LOW |
—
|
— | — | — | 1 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access | Details | |
| 30 Jul 2026 | CRITICAL 9.8 |
0.0%
|
LOW |
—
|
— | — | — | 1 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n | Details | |
| 30 Jul 2026 | HIGH 8.8 |
0.0%
|
LOW |
—
|
— | — | — | 0 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows | Details | |
| 30 Jul 2026 | HIGH 8.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, w | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack | Details | |
| 30 Jul 2026 | HIGH 7.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe | Details | |
| 30 Jul 2026 | MEDIUM 6.5 |
0.0%
|
LOW |
—
|
— | — | — | 0 | CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj | Details | |
| 30 Jul 2026 | CRITICAL 9.1 |
0.0%
|
LOW |
—
|
— | — | — | 0 | CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo | Details | |
| 30 Jul 2026 | CRITICAL 9.3 |
0.0%
|
LOW |
—
|
— | — | — | 1 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with | Details | |
| 30 Jul 2026 | HIGH 7.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment pr | Details | |
| 30 Jul 2026 | — |
0.0%
|
— |
—
|
— | — | — | 0 | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP | Details | |
| 30 Jul 2026 | MEDIUM 4.3 |
0.0%
|
LOW |
—
|
— | — | — | 0 | The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24 | Details | |
| 30 Jul 2026 | MEDIUM 6.8 |
0.0%
|
LOW |
—
|
— | — | — | 0 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able | Details | |
| 30 Jul 2026 | HIGH 7.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r | Details | |
| 30 Jul 2026 | HIGH 7.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t | Details | |
| 30 Jul 2026 | — |
0.0%
|
— |
—
|
— | — | — | 0 | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions | Details | |
| 30 Jul 2026 | — |
0.0%
|
— |
—
|
— | — | — | 0 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f | Details | |
| 30 Jul 2026 | HIGH 7.2 |
0.0%
|
LOW |
—
|
— | — | — | 0 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and | Details | |
| 30 Jul 2026 | HIGH 8.8 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could al | Details | |
| 30 Jul 2026 | HIGH 8.3 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could al | Details | |
| 30 Jul 2026 | HIGH 8.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau | Details | |
| 30 Jul 2026 | MEDIUM 5.8 |
0.0%
|
LOW |
—
|
— | — | — | 0 | A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns | Details | |
| 30 Jul 2026 | — |
0.0%
|
— |
—
|
— | — | — | 0 | A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17. | Details | |
| 30 Jul 2026 | MEDIUM 5.9 |
0.0%
|
HIGH |
—
|
— | — | — | 0 | The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo | Details | |
| 30 Jul 2026 | HIGH 7.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the | Details | |
| 30 Jul 2026 | HIGH 7.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the | Details | |
| 30 Jul 2026 | MEDIUM 5.9 |
0.0%
|
HIGH |
—
|
— | — | — | 0 | The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a | Details | |
| 30 Jul 2026 | MEDIUM 4.2 |
0.0%
|
HIGH |
—
|
— | — | — | 0 | The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Sto | Details | |
| 30 Jul 2026 | HIGH 7.6 |
0.0%
|
LOW |
—
|
— | — | — | 0 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the | Details | |
| 30 Jul 2026 | — |
0.0%
|
— |
—
|
— | — | — | 0 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __ | Details | |
| 30 Jul 2026 | — |
0.2%
|
— |
—
|
— | — | — | 0 | PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer a | Details | |
| 30 Jul 2026 | CRITICAL 9.8 |
0.4%
|
LOW |
—
|
— | — | — | 0 | Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into | Details |